Information Security Business Analyst

  • Full-time

Company Description

A3T, a fast growing ISO 27001, 9001, and 20000 certified company, specializes in Defensive Cyber Security Services and Solutions, driven by our customer's mission, and delivering excellent 'A' level talented personnel and an unparalleled customer satisfaction experience.

Join A3T and watch your career soar! A3T is an agile and mature company looking for incredible talent to support the U.S/ Government in many important national security roles.  A3T is looking to bring on an experienced, Secret cleared, Information Security Business Analyst with “Next-Level Thinking” who is ready to take their career to a new level with A3T.

Job Description

The successful candidate shall provide cybersecurity analysis expertise, determines, develops and implements enterprise information security standards and procedures.  The Information Security Business Analyst shall support evaluation of the current cybersecurity workforce composition and organizational structure. The goal is to understand proper cybersecurity workforce reporting lines, implement efficient and sound structure and enhance the effectiveness of cybersecurity services delivery. As required, support this DoD agency in developing and executing a reorganization package.

Duties/Responsibilities:

  • Assess Workforce Structure – identify best practices for cybersecurity workforce reporting, supervision and oversight. 

  • Assess current “As Is” cybersecurity workforce structure against best practices and recommend changes in organizational alignment. 

  • Document results and recommendations in an actionable whitepaper.

  • Support Organizational Realignment – As required, provide support in developing a cybersecurity reorganization package including developing “As Is” and “To Be” organizational charts, “To Be” mission and function statements, business case analysis, budget impact analysis, and concept briefings.

  • Conduct Skill Gap Analysis – Identify status of cybersecurity employee knowledge, education, training and certification against standards identified in the Defense Cybersecurity Work Force which leverages the original National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework (NCWF) and the DoD Joint Cyberspace Training and Certification Standards (JCT&CS).

  • Make recommendations to close gaps through training. 

  • Develop position-type specific training plans (e.g. Information System Security Manager, Cyber Security Service Provider, etc.). 

  • Develop a training needs gap analysis that includes recommended sources to procure training or to recommendations to develop in-house training to address project-specific topics.

  • Enhance CS Workforce Program - Analyze current resources, technologies, personnel supporting CS workforce program, identifying deficiencies and needs for processes, people and tools. 

  • Document analysis results to include strengths and weaknesses in an actionable whitepaper.

  • Support senior ISSM in developing plan of actions and milestones.

  • Draft proposed CS Workforce program process flows to include roles and responsibilities, end to end. 

  • Ensure thorough identification of best business practices, sound CS Workforce management methods and processes to including methods for identification of CS workforce requirements and addressing rolls of all phases of the system development lifecycle.

  • Recommend industry tool solutions for managing, verifying, tracking and reporting both at the enterprise level and system level.   Must include system and enterprise metrics and compliance reports and be aligned and link back to NIST and DoD security control requirements.

Qualifications

Security Clearance:  Secret (Active)

Technical Certifications:  

  • Information Assurance Management (IAM) level III.  Certified Information Systems Security Professional (CISSP) or other Equivalent (CISM or GLSC) DoD 8570.01-M

Experience:

  • Must have minimum 10 years of experience in cybersecurity. 

  • Must have strong critical thinking/analytical skills, creativity, a proven drive for quality, and excellent oral and written communication skills.

  • Must have strong technical writing skills.

  • Able to work under only general direction and be able to independently determine and develop an approach to information system security solutions, only needing review upon completion for adequacy in meeting objectives.

  • Strong organizational skills and an ability to stay focused while managing multiple tasks concurrently.

  • Must have working knowledge of the DoD CS policy requirements set forth in Dodi 8500.01, “Cybersecurity,” and DoDI 8510.01, “Risk Management Framework (RMF) for DoD Information Technology,” and their successors. Available at http://www.dtic.mil/

Additional Information

We offer a competitive benefits package to include: paid holidays, paid time off, medical, dental, vision, company paid long and short term disability and life insurance, referral bonuses, certification reimbursement program, 401K matching, etc.

It is the policy of A3T to provide equal opportunity in recruiting, hiring, training, and promoting individuals in all job categories without regard to race, color, religion, national origin, gender, age, disability, genetic information, veteran status, sexual orientation, gender identity, or any other protected class or category as may be defined by federal, state, or local laws or regulations.

We maintain a drug-free workplace and perform pre-employment substance abuse testing to include background checks  and eVerify validation.